Cross-source coverage

T1008 / ATT&CK

Fallback Channels

9 rules across 5 sources.

Showing deprecated rules · back to the default

From MITRE ATT&CK 19.2

Adversaries may use fallback or alternate communication channels if the primary channel is compromised or inaccessible in order to maintain reliable command and control and to avoid data transfer thresholds.

Platforms
ESXi · Linux · macOS · Windows
Telemetry
WinEventLog:SysmonNSM:Flowauditd:SYSCALLmacos:unifiedlogesxi:vmkernelesxi:vpxd

How MITRE says to detect it DET0499

Behavioral Detection of Fallback or Alternate C2 Channels

Windows Analytic 1376

Establishing network connections on uncommon ports or protocols following C2 disruption or blocking. Often executed by processes that typically exhibit no network activity.

  • WinEventLog:Sysmon EventCode=3, 22
  • NSM:Flow uncommon ports

Linux Analytic 1377

Creation of outbound connections on alternate ports or using covert transport (e.g., ICMP, DNS) from non-network-intensive processes, following known disruption or blocked traffic.

  • auditd:SYSCALL outbound connections
  • NSM:Flow alternate ports

macOS Analytic 1378

Outbound fallback traffic from low-profile or background launch agents using unusual protocols or destinations after primary channel inactivity.

  • macos:unifiedlog None
  • NSM:Flow None

ESXi Analytic 1379

Outbound traffic from host management services or guest-to-host interactions over unusual interfaces (e.g., backdoor API endpoints or external VPN tunnels).

  • esxi:vmkernel None
  • esxi:vpxd None

SigmaHQ/sigma

4 rules
Detection Severity Format
Outlook Macro Execution Without Warning Setting Enabled High Sigma
Potential Persistence Via Outlook LoadMacroProviderOnBoot Setting High Sigma
Suspicious Outlook Macro Created High Sigma
New Outlook Macro Created Medium Sigma

Azure/Azure-Sentinel

2 rules
Detection Severity Format
Excessive NXDOMAIN DNS Queries (ASIM DNS Schema) Medium KQL
Potential DGA detected (ASIM DNS Schema) Medium KQL

chronicle/detection-rules

1 rule
Detection Severity Format
possible_bind_or_reverse_shell_via_netcat_auditbeat_for_linux Undefined YARA-L

elastic/protections-artifacts

1 rule
Detection Severity Format
OsaScript Download Cradle Spawned Undefined Elastic TOML

splunk/security_content

1 rule
Detection Severity Format
Windows Outlook Macro Security Modified Undefined SPL

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.